. .

Site Menu


What's New?


Hot Topics


2008-2009 IT Security Implementation Plan update!

The dates for the quarterly implementation plan submissions have been updated to reflect the 2008-2009 schedule.


Incident Response

FACTA Red Flags FAQ

Below are commonly asked questions about the FACTA Red Flags regulation.

  1. What is the purpose of the FACTA Red Flags regulation?
  2. What is covered by the regulation?
  3. What is the definition of a financial institution or creditor?
  4. What steps are necessary for the university to take?
  5. What are the 26 red flags outlined in the regulation?
  6. Who should I contact if I have more questions?

Further Questions?

Please use the email form at the bottom of the page to contact us.


What is the purpose of the FACTA Red Flags regulation?

The purpose of the regulation is to detect and prevent identity theft by defining red flags or alerts that refer to a pattern, practice, or specific activity that indicates the possible existence of identity theft.

What is covered by the regulation?

Financial institutions and creditors (see definition below) with covered accounts are required to develop and implement identity theft prevention programs.

What is the definition of a financial institution or creditor?

The Federal Trade Commission has defined this very broadly as anyone who defers payment on a debt or anyone who defers payment on goods or services. Furthermore, a creditor is:
  • Any entity that regularly extends, renews or continues credit
  • Any entity that regularly arranges for the extension, renewal or continuation of credit
  • Any assignee of an original creditor who is involved in the decision to extend, renew or continue credit
Based on this definition, there are many units at the university that sell goods and/or services with deferred payment (e.g. accounts receivable).

What steps are necessary for the university to take?

The university must develop a policy and program to identify and detect the relevant warning signs or red flags of identity theft. The policy must be approved by university leadership. University units will need to be educated on the appropriate actions steps that need to be taken when a red flag occurs.

What are the 26 red flags outlined in the regulation?

The complete list of red flags outlined in the regulation is available here: Red Flags

Who should I contact if I have more questions?

Contact Joyce Wagner (wagner.21), Data Privacy Administrator at (614) 247-8206 or use the e-mail form below.

Further Questions?

If your question is not listed in the above FAQ, please use the form below to contact the Identity Theft Red Flags support staff. We will respond to your inquiry as soon as possible.

Your Name:

Your e-mail address:

If phone contact is preferred, the phone number where you can be reached:

What is your primary role at the university? (e.g. Faculty, Staff, GA, Student)

Message:

Please enter the word(s) shown below in the "Captcha" box. This helps prevent spam from filling our email so we can focus on legitimate questions like yours.